Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Attackers exploited a critical zero-day in Citrix NetScaler appliances for more than three weeks before detection, compromising organizations across government, finance, education, telecom, legal, and professional services sectors in North America and Europe. Mandiant and Citrix also disclosed a second actively exploited NetScaler flaw, with researchers warning of broad and opportunistic exploitation by suspected state-sponsored threat actors. #Citrix #NetScaler #CVE-2026-88772 #CVE-2026-88771 #Mandiant

Keypoints

  • Attackers exploited CVE-2026-88772 weeks before it was confirmed.
  • Dozens of organizations across multiple sectors were likely compromised.
  • A second NetScaler zero-day, CVE-2026-88771, was also actively abused.
  • Researchers found novel tools for tunneling, reconnaissance, and credential theft.
  • Mandiant expects more widespread exploitation of both vulnerabilities.

Read More: https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/